Vulnerability library
Security checkMarch 25, 2026

SVG Injection via Unsanitized Options in @dicebear/core and @dicebear/initials - @dicebear/core

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpm@dicebear/core

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

SVG attribute values derived from user-supplied options (backgroundColor, fontFamily, textColor) were not XML-escaped before interpolation into SVG output. This could allow Cross-Site Scripting (XSS) when applications pass untrusted input to createAvatar() and serve the resulting SVG inline or with Content-Type: image/svg+xml.

Recommendation

Update the @dicebear/core package to the latest compatible version. Followings are version details:

  • Affected version(s): **>= 9.0.0, <= 9.4.0 >= 8.0.0, <= 8.0.2 >= 7.0.0, <= 7.1.3 >= 6.0.0, <= 6.1.3 >= 5.0.0, <= 5.4.3**
  • Patched version(s): **9.4.1 8.0.3 7.1.4 6.1.4 5.4.4**

References

Could your website be exposed too?

SmartScanner can check your website for SVG Injection via Unsanitized Options in @dicebear/core and @dicebear/initials - @dicebear/core and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated March 25, 2026